What is CVE-2026-14926?
An authorization bypass vulnerability has been identified in the FluentCart WordPress plugin. This flaw allows any authenticated customer to perform actions on another customer's subscription, such as changing the payment method or canceling it. Immediate update to version 1.4.0 or higher is required to mitigate this issue.
Azərbaycanca: FluentCart WordPress plaginində autentifikasiya yoxlanışı zəifliyi aşkarlanıb. Bu boşluq autentifikasiya olunmuş istənilən müştəriyə başqa müştərinin abunəliyi üzərində ödəniş metodunu dəyişmək və ya abunəliyi ləğv etmək kimi əməliyyatlar aparmağa imkan verir. Təsirə məruz qalmamaq üçün plagin dərhal 1.4.0 və ya daha yuxarı versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Which plugin is affected by this authorization bypass vulnerability?
The authorization bypass vulnerability discovered in the FluentCart WordPress plugin allows any authenticated customer to perform actions on another customer's subscription.
To which version should the FluentCart plugin be updated to fix this vulnerability?
To mitigate this issue, an immediate update to version 1.4.0 or higher is required.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.